Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multiple PFsense in different Servers, talk to each for assigning DHCP

    Scheduled Pinned Locked Moved Routing and Multi WAN
    7 Posts 5 Posters 998 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P Offline
      pedrito
      last edited by

      Dear Pfsense Friends

      I have a few servers on OVH, where I have the IP Failovers that are used for each pfsense

      I was wondering if there is a way to make a kind of configuration

      Where PFsense VMS talk to each other and then redirect the traffic for example

      If:

      192.168.1.2 is in server 1, they always redirect traffic there

      If someone wants to talk to 192.168.1.5, they redirect traffic to the vm in pfsense server 5

      Thanks in advance for your help

      Pedro

      1 Reply Last reply Reply Quote 0
      • P Offline
        pedrito
        last edited by

        the pfsense servers know each other via WAN (Ip Failovers)

        1 Reply Last reply Reply Quote 0
        • H Offline
          heper
          last edited by

          i have no clue what you want to do … could you make a network diagram and try to explain 'the plan' with a lot more detail?

          1 Reply Last reply Reply Quote 0
          • KOMK Offline
            KOM
            last edited by

            Sounds like Multi-WAN and policy-based routing?

            https://doc.pfsense.org/index.php/Category:Multi-WAN

            1 Reply Last reply Reply Quote 0
            • P Offline
              pedrito
              last edited by

              thx for the input, just found it

              its called site to site

              https://doc.pfsense.org/index.php/OpenVPN_Site_To_Site

              or

              https://doc.pfsense.org/index.php/Routing_internet_traffic_through_a_site-to-site_IPsec_tunnel

              My question is, I want the pfsense site1, or site2, or site3 to still be able to communicate to the internet to use the server's 1 gbps speed and not route everything through pfsense sitex

              So I think openvpn is the best right?

              It will route only LAN networks

              sorry a newbie in routers here

              1 Reply Last reply Reply Quote 0
              • P Offline
                phil.davis
                last edited by

                Yes, you can have multiple site-to-site links between various offices in a mesh or just the connections you actually want.
                You can direct whatever traffic you like across those - just the intranet traffic between offices for you internal private IP addresses, or send all or part of your outgoing internet traffic to another office first if you have a need for that.
                For me, OpenVPN "just works". Because of that, I have never even bothered with IPsec.

                As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                1 Reply Last reply Reply Quote 0
                • F Offline
                  FJSchrankJr
                  last edited by

                  @heper:

                  i have no clue what you want to do … could you make a network diagram and try to explain 'the plan' with a lot more detail?

                  Agreed. I was trying to figure that out too. Thats why I ask for short descriptions and config files (obscured IPs, etc, better than pictures)

                  FJS - Embedded Systems Engineer
                  Pictures are worth a thousand words, but <u>posting config.xml backups are worth 10,000</u>.  Alter the IPs, change anything revealing but leave subnets intact. Use find and replace. Please try to keep it brief on the description.
                  ALWAYS disable TSO  & LRO EXCEPT CHKSUM IF SUPPORTED. TSO/LRO breaks traffic, pf scrub and this goes for any passive device inline

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.